#23981 [Asn->Csd]: bcompiler doesn't check the return value of php_stream_open_wrapper()
| From: | alan_k@php.net | Date: | Fri, 06 Jun 2003 09:03:06 +0000 |
| Subject: | #23981 [Asn->Csd]: bcompiler doesn't check the return value of php_stream_open_wrapper() | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-17108@lists.php.net to get a copy of this message | ||
ID: 23981
Updated by: alan_k@php.net
Reported By: per at nobolt dot com
-Status: Assigned
+Status: Closed
Bug Type: PEAR related
Operating System: Debian GNU/Linux
PHP Version: 4.3.2
Assigned To: alan_k
New Comment:
thanks - added to release + a few more checks that should help..
Previous Comments:
------------------------------------------------------------------------
[2003-06-03 07:33:34] spam at nobolt dot com
This bug is very serious since it causes segmentation faults on every
missing file in include(), require() etc. (since bcompiler hooks into
the Zend core). This patch will fix it:
Index: bcompiler.c
===================================================================
RCS file: /repository/pear/PECL/bcompiler/bcompiler.c,v
retrieving revision 1.39
diff -u -r1.39 bcompiler.c
--- bcompiler.c 8 Apr 2003 07:59:44 -0000 1.39
+++ bcompiler.c 3 Jun 2003 12:29:51 -0000
@@ -215,6 +215,10 @@
BCOMPILER_DEBUG(("no bz2 support - opening it..\n"));
stream = php_stream_open_wrapper(file_name, "rb", ENFORCE_SAFE_MODE |
REPORT_ERRORS, NULL);
+ if (!stream) {
+ return stream;
+ }
+
/* Sanity check to see if it is a bzip2 encoded stream */
php_stream_read(stream, magic, sizeof(magic));
if (memcmp(magic, "BZ", 2) == 0) {
The only problem with this patch is that you get the warning about the
missing file twice, but IMO that's much better than a segmentation
fault.
------------------------------------------------------------------------
[2003-06-03 06:35:42] per at nobolt dot com
In the bz2_aware_stream_open(), there is code like this:
BCOMPILER_DEBUG(("no bz2 support - opening it..\n"));
stream = php_stream_open_wrapper(file_name, "rb", ENFORCE_SAFE_MODE |
REPORT_ERRORS, NULL);
/* Sanity check to see if it is a bzip2 encoded stream */
php_stream_read(stream, magic, sizeof(magic));
If the call to php_stream_open_wrapper() fails (which it will if the
file does not exist), stream will be NULL and this will cause a
segmentation fault in php_stream_read().
This can easily be fixed by just checking the return value; if it is
NULL, return from the function immediately.
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=23981&edit=1